Added sample security. Though this breaks the app.

This commit is contained in:
2024-04-01 18:58:20 +02:00
parent 9a84967804
commit 4e43df8075
3 changed files with 51 additions and 0 deletions

View File

@ -0,0 +1,17 @@
package de.w665.sharepulse.config;
import jakarta.servlet.FilterChain;
import jakarta.servlet.ServletException;
import jakarta.servlet.ServletRequest;
import jakarta.servlet.ServletResponse;
import org.springframework.web.filter.GenericFilterBean;
import java.io.IOException;
public class CustomAuthenticationFilter extends GenericFilterBean {
@Override
public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
// Custom logic here
filterChain.doFilter(servletRequest, servletResponse);
}
}

View File

@ -0,0 +1,29 @@
package de.w665.sharepulse.config;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.Customizer;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configurers.LogoutConfigurer;
import org.springframework.security.web.SecurityFilterChain;
@Configuration
@EnableWebSecurity
public class SecurityConfig {
@Bean
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http
.authorizeHttpRequests(authorize -> authorize
.requestMatchers("/admin/**").authenticated()
.anyRequest().permitAll()
)
.formLogin(formLogin -> formLogin
.loginPage("/login")
.permitAll()
)
.logout(LogoutConfigurer::permitAll)
.rememberMe(Customizer.withDefaults());
return http.build();
}
}